I was reading some posts on the Full-disclosure mailing list and came across the some posts relating to WPA hacking (WPA attack improved to 1min). After spending hundreds of hours using the AIR tools to crack WEP encryption and looking into networks as part of my previous job, I was very interested to see how things are progressing.
A few years back, some friends and I were messing around with a Taco Bellâ€™s drive-thru frequencies. RijilV and isotek showed me how easy it was to hijack the frequencies of just about any fast food restaurant with a very simple mod to a ham radio. The radios they used were Yaesu VX-5 and VX-7 models. We had a few weeks of occasional fun, sitting a few parking lots away and saying all kinds of horrible things to potential fast food customers. For the most part, I didnâ€™t record any of it. But you can find a few clips of our fast food hijinks if you scroll down on the PLA Sound Clips Archive page.
Finally we decided to capture a bit of our FCC violations on video. But instead of capturing actual customers being harassed by us as they placed an order, I drove through the Taco Bell drive-thru myself with a video camera sitting on the dashboard. As I attempted to place my order, RijilV informed me of some crazy new Taco Bell policies and a manager immediately rushed out to explain to me that I wasnâ€™t actually talking to an employee. Here is that video:
After spending several years on Google Video and YouTube, itâ€™s been watched approximately 20,000 times. And of those 20,000 people who have viewed it, approximately all of them have emailed me and asked me what kind of radio we used and how can they use a radio to do the same thing. So in the spirit of April 1st and in order to quell the number of emails sent to me and posts on the PLA Forums asking the same thing, Iâ€™ve decided to write this tutorial to help those people out.
But Iâ€™m not going to explain how to modify a Yaesu VX5 or a Yaesu VX7. A simple Googlesearch will show you how to modify these ham radios. The problem with these mods is that, even though theyâ€™re fairly simple, you have to buy the radios which could cost you anywhere from $200 – $400. Then, after removing a couple solder points, you have to learn how to use it, you have to look up fast food frequency lists, you have to understand the difference between the transmit frequencies and the receive frequencies and you have to scroll through PL tones using trial and error to find the correct one.
Or how about we do this a different way. A way that uses a couple items that you might already have in your home. You can easily modify most old CB radios in a way that will allow them to transmit directly to drive-thru frequencies. You wonâ€™t have to scroll through hundreds of possible drive-thru frequencies, because a CB radioâ€™s channels line up in exactly the same way as most drive-thruâ€™s channels, only at a higher frequency. How do you get your CB radio to run at a higher frequency? A simple replacement of the crystal inside, with a 6.5536 MHz crystal. This triples the megahertz that are broadcast on and there is no learning required. You just take the modified CB radio to a fast food restaurant and start broadcasting to the customers.
â€œBut RBCP, I donâ€™t have a 6.5536 MHz crystal lying around my house,â€ you might be whining at this point. But this isnâ€™t true. Just about any house has several 6.5536 MHz crystals in them if you know where to look. This just happens to be the exact same crystal that you can find in electric heaters, hair dryers, electric stoves, curling irons, electric hot water heaters, irons, and toasters. These crystals are in just about any item that has heated coils and are used to control the frequency of the heating elements so that they donâ€™t burn your house down.
So for this modification you needâ€¦
1 CB radio. It has to be a 40 channel CB radio with a digital display, which includes just about any CB radio manufactured after the mid 1980â€™s. The old 23 channel CBs from the 1970â€™s will not work. It can even be a walkie talkie CB radio. If you donâ€™t have one, you can find one at Goodwill or a yard sale for probably less than $10.
1 toaster. (Or other item with heating elements inside.) A toaster is the most ideal to use, because itâ€™s almost guaranteed to have the crystal inside of it. Itâ€™s more common to find curling irons and hair dryers that donâ€™t. Again, it should be a toaster manufactured within the past 20 years or so. Before that they didnâ€™t have crystal requirements for toaster manufacturers. (And incidentally, there were a lot more electrical house fires back then.) Goodwill will probably have a toaster for less than $10.
1 soldering iron and solder. Donâ€™t worry if you donâ€™t have soldering experience. Itâ€™s actually pretty easy. Click here for a soldering tutorial. You can purchase a soldering iron at Radio Shack or Sears for about $10.
A few screwdrivers
Even if you have to buy all these materials, youâ€™re only out $30. Thatâ€™s a lot better than the $300 you might end up spending on a Yaesu radio. And some of you might already have all these items so you donâ€™t have to pay anything. Ask a friend or a relative if theyâ€™ve got an old toaster or CB radio lying around that they donâ€™t need.
First youâ€™ll want to take apart your toaster. This isnâ€™t too hard. Just flip it upside down and start removing the screws. Youâ€™ll probably need to pull off the plastic lever and knobs before you remove the top of the toaster. Once you have the top off, youâ€™ll see a green or brown circuit board inside.
Flip the circuit board down and youâ€™ll see all the components on the other side, including the 6.5536 MHz crystal. The crystal is silver and will have 6.5 stamped on the side of it. In the picture below, Iâ€™ve used an arrow to show you where itâ€™s located.
The crystal is likely in a different spot in other toasters, but itâ€™s hard to mistake for any other electronic component. The crystal will have some form of 6.5 stamped on the side of it. In my toaster, it showed 6.55-12. While the official frequency needed is 6.5536 MHz, anything within 1.6 megahertz will work. So donâ€™t worry if your crystal just says 6.5 or 6.50 – itâ€™s all the same for our purposes.
Itâ€™s kind of hard to see what Iâ€™m doing in the picture above, but Iâ€™m heating up the leads on the crystal from underneath with my soldering iron to melt the solder, and Iâ€™m pulling on the crystal from above with a pair of needle nose pliers. It only takes a few seconds to get the crystal out of the toaster.
Now that the crystal is out of your toaster, throw your toaster away! Do not attempt to use it once the crystal is removed. Remember, the crystal is in there for safety and using your toaster without the crystal could burn your toast and/or start a kitchen fire. Itâ€™s likely your toaster wonâ€™t even turn on with the missing crystal, but please donâ€™t even try. Just throw it away.
As I mentioned before, just about any brand and model of CB radio will work, as long as it has the digital display on it. Which means, just about any CB radio manufactured after the mid 1980â€™s. These are the kinds of CB radios whose frequencies are controlled by a single crystal inside of them. For my mod, I used a Radio Shack TRC-207 walkie talkie CB radio, which is pictured above. I prefer using a walkie talkie CB radio because it doesnâ€™t requiring sticking a huge CB antenna on the roof of my car which might be noticed if a fast food employee starts looking around the parking lot for the culprits.
Taking apart your CB radio is just as easy as taking apart the toaster. Remove the screws and pop it open. You may or may not have to lift up the circuit board inside to find the crystal inside. In my particular model, the crystal actually plugged into a socket so I didnâ€™t need to even desolder the old crystal. I just pulled it out with my fingers and then plugged in the new 6.55 MHz crystal. I donâ€™t know how common this is, because in other CB radios that Iâ€™ve modified the crystal was soldered to the circuit board, just like in the toaster.
Put your CB back together and test it to make sure itâ€™s working. Youâ€™re finished! Obviously, you wonâ€™t be able to talk on normal CB channels anymore since your CB is transmitting and receiving at a much higher frequency now. But who cares, CB channels are lame anyway. Letâ€™s hop in the car and drive to our nearest fast food establishment to test it out.
Sit near the drive-thru and wait for a customer to pull up. While the customer is talking to the drive-thru speaker, start flipping through your channels until you hear them talking. Iâ€™ve found that most drive thrus end up being somewhere in the 16 – 25 channel range. Iâ€™ve never found one above channel 30 and only a few on channels 1 through 15. It all depends on how their drive-thru is set up and what frequencies theyâ€™re using. Anyway, push down your talk button and start talking to the customer.
The cool thing about using a CB radio to transmit on drive-thru frequencies is that a CB is designed to work for several miles. The headsets that those fast food people wear are only designed to work for about 100 feet. So you can easily overpower the employees, even if youâ€™re several parking lots away. In fact, you may be inadvertently screwing with several other drive-thrus in town without even knowing it. This is more likely when youâ€™re using the kind of CB radio thatâ€™s supposed to be installed in a car. Those usually run on 5 watts and can cover an entire city. This is another reason I like to use my walkie talkie. Itâ€™s lucky if it will work for even a mile, so Iâ€™m only harassing one restaurant at a time.
If you found this tutorial useful, you might also enjoy the video Iâ€™ve made on the same subject. It includes much of the same information in this tutorial, but also includes actual footage of us messing with a drive-thru with this CB mod. Enjoy!